Microsoft Copilot security directory
SAP
Published by Microsoft
Medium risk
SAP Application Server and Message Server messages
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 19 tools or capabilities.
- [BAPI - RFC] Close stateful session
- [BAPI - RFC] Create stateful session
- [BAPI] Call method in SAP (Preview)
- [BAPI] Commit transaction
- [BAPI] Roll back transaction (Preview)
- [IDOC - RFC] Confirm transaction Id
- [IDOC] Get IDOC list for transaction
- [IDOC] Get IDOC status
- [IDOC] Send document to SAP
- [IDOC] Send document to SAP (deprecated) (Preview)
- [RFC] Add RFC to transaction (Preview)
- [RFC] Call function in SAP (Preview)
- [RFC] Call function in SAP (V2) [DEPRECATED]
- [RFC] Call function in SAP (V3) (Preview)
- [RFC] Call long-running function in SAP (Preview)
- [RFC] Commit transaction (Preview)
- [RFC] Create transaction
- [RFC] Get transaction
- Generate schemas
- Read SAP table (obsolete) [DEPRECATED]
- Read SAP table (Preview)
- Send message to SAP
The interactive security report will load automatically.